Viewing Attackers And Targets; Configuring And Viewing Threat Statistics; Configuring Threat Statistics - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Chapter 23
Preventing Network Attacks
The following is sample output from the show threat-detection shun command:
hostname# show threat-detection shun
Shunned Host List:
10.1.1.6
198.1.6.7

Viewing Attackers and Targets

To view the hosts that the security appliance decides are attackers (including hosts on the shun list), and
to view the hosts that are the target of an attack, enter the following command:
hostname# show threat-detection scanning-threat [attacker | target]
If you do not enter an option, both attackers and target hosts are displayed.
The following is sample output from the show threat-detection scanning-threat attacker command:
hostname# show threat-detection scanning-threat attacker
10.1.2.3
10.8.3.6
209.165.200.225

Configuring and Viewing Threat Statistics

You can configure the security appliance to collect extensive statistics. Threat detection statistics show
both allowed and dropped traffic rates. To view statistics for basic threat detection, see the
Basic Threat Statistics" section on page
Enabling statistics can affect the security appliance performance, depending on the type of statistics
Caution
enabled. The threat-detection statistics host command affects performance in a significant way; if you
have a high traffic load, you might consider enabling this type of statistics temporarily. The
threat-detection statistics port command, however, has modest impact.
This section includes the following topics:

Configuring Threat Statistics

By default, statistics for access lists are enabled. To enable all statistics, enter the following command:
hostname(config)# threat-detection statistics
To enable only certain statistics, enter one or more of the following commands.
OL-12172-03
Configuring Threat Statistics, page 23-7
Viewing Threat Statistics, page 23-8
To enable statistics for access lists (if they were disabled previously), enter the following command:
hostname(config)# threat-detection statistics access-list
Access list statistics are only displayed using the show threat-detection top access-list command.
To enable statistics for hosts, enter the following command:
hostname(config)# threat-detection statistics host
23-4. By default, statistics for access lists are enabled.
Cisco Security Appliance Command Line Configuration Guide
Configuring Threat Detection
"Managing
23-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents